基于攻防博弈的网络系统动态风险评估模型
CSTR:
作者:
作者单位:

作者简介:

通讯作者:

中图分类号:

基金项目:


A dynamic risk assessment model for network systems
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    针对现有模型在处理开源软件供应链中复杂依赖关系和潜在威胁路径时过于简化,难以应对大数据时代背景下网络系统中的开源风险问题,提出基于攻防博弈的网络系统动态风险评估模型。首先,整合系统拓扑结构信息、开源组件信息以及漏洞信息构建开源风险传播知识图谱;其次,基于知识图谱设计威胁路径生成算法以获取威胁路径,并评估其潜在风险,确定最大可能威胁路径;最后,引入随机博弈的思想,建立基于风险博弈的网络系统风险评估模型NSRAM-RG,分析攻防双方针对最大可能威胁路径的博弈行为,动态更新知识图谱,并依据双方效用函数来量化评估网络系统的风险。结果表明,所提模型的评估结果与真实值的拟合程度优于HMM(隐马尔可夫模型)和AHP(层次分析法),能够更准确地反映系统的风险变化。所提模型能够有效地量化评估系统中的开源风险,为开源软件供应链的安全管理提供了新的思路。

    Abstract:

    A dynamic risk assessment model for network systems based on attack and defense game theory was proposed to address the problem that the existing models are overly simplified in dealing with the complex dependencies and potential threat paths in the open source software supply chain,and it is difficult to cope with the problem of open source risks in network systems under the background of the big data era. Firstly,system topology information,open source component information,and vulnerability information were integrated to build a knowledge graph of open source risk propagation; Secondly,a threat path generation algorithm was designed based on knowledge graphs to acquire threat paths,and the potential risks of each threat path were evaluated to identify the most likely threat path; Finally,the idea of stochastic game theory was introduced to establish NSRAM-RG,a risk assessment model of network system based on risk game,to analyze the game behaviors of the attacker and defender regarding the most likely threat path. The knowledge graph was dynamically updated,and the risk of the network system was quantitatively evaluated according to the utility function. The experimental results show that fitting degree of the assessment results to the true values is better than the HMM and AHP methods,which can more accurately respond to the risk changes of the system. The proposed model can effectively quantify and assess the open source risk in the system,which provides a new idea for the security management of the open source software supply chain.

    参考文献
    相似文献
    引证文献
引用本文

张红斌,米佳美,左 珺,刘 滨.基于攻防博弈的网络系统动态风险评估模型[J].河北科技大学学报,2025,46(3):342-354

复制
相关视频

分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2024-10-18
  • 最后修改日期:2024-12-10
  • 录用日期:
  • 在线发布日期: 2025-07-02
  • 出版日期:
文章二维码